SuSE: 2012:0983-1: important: puppet
Summary
The following bugs have been fixed in puppet:
* bnc#770828, CVE-2012-3864: puppet: authenticated
clients can read arbitrary files via a flaw in puppet master
* bnc#770829, CVE-2012-3865: puppet: arbitrary file
delete / Denial of Service on Puppet Master by
authenticated clients
* bnc#770833, CVE-2012-3867: puppet: insufficient input
validation for agent certificate names
Security Issue references:
* CVE-2012-3867
References
#770828 #770829 #770833
Cross- CVE-2012-3864 CVE-2012-3865 CVE-2012-3867
Affected Products:
SUSE Linux Enterprise Server 11 SP2
SUSE Linux Enterprise Server 11 SP1 for VMware
SUSE Linux Enterprise Server 11 SP1
SUSE Linux Enterprise Desktop 11 SP2
SUSE Linux Enterprise Desktop 11 SP1
https://www.suse.com/security/cve/CVE-2012-3864.html
https://www.suse.com/security/cve/CVE-2012-3865.html
https://www.suse.com/security/cve/CVE-2012-3867.html
https://bugzilla.novell.com/770828
https://bugzilla.novell.com/770829
https://bugzilla.novell.com/770833
https://login.microfocus.com/nidp/app/login